zapper-nft[.]io
“Zapper”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
This domain, zapper-nft.io, was observed to resolve to the IP address 104.21.32.1, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative name servers are demi.ns.cloudflare.com and ned.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s edge network. Registration information shows the domain was created on August 06, 2025 and was purchased through Dynadot LLC. No SSL certificate was presented during connection attempts, and the site returned an HTTP response indicating it is currently taken offline. The page title returned by the server is “Zapper”, which does not correspond to the targeted brand. However, threat intelligence classifies the activity as a brand impersonation campaign targeting the foundation brand, and the domain name has been flagged accordingly.
VirusTotal analysis recorded three detections out of ninety‑five scanned security vendors, confirming that at least a subset of scanners identified malicious characteristics. Independent security services have also listed the domain on a single blocklist, and PhishDestroy has recorded it as blocked. The Gridinsoft trust score of zero out of one hundred further reflects a high confidence of malicious intent. The combination of a recent registration, use of a reputable CDN service without TLS, a generic page title, and multiple vendor detections aligns with typical infrastructure patterns employed in brand‑impersonation operations.
Because the domain is presently offline, direct content inspection could not be performed, leaving the exact phishing payload and user‑facing elements unverified. Defenders should continue to block the IP address 104.21.32.1 for traffic originating from zapper-nft.io, add the domain to internal deny lists, and monitor for any re‑registration attempts or related sub‑domains using the same Cloudflare name servers. Ongoing observation of the associated ASN and registrar may reveal future infrastructure reuse.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 10/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.